NETLOCK delayed revocation incident involving policy qualifiers in TLS certificates
NETLOCK reported that some TLS certificates containing policy qualifiers other than id-qt-cps were not revoked within the required timeframe. The incident report said the affected certificates were discovered after a zlint check on a certificate issued under NETLOCK Trust EV CA 3, and that the issue also affected certificates issued under NETLOCK Trust Qualified EV CA 3 and NETLOCK DVSSL CA. NETLOCK said it began customer communication, started revocations on 2024-04-06, revoked the misissued certificates not requested to remain valid by 2024-04-09, and later revoked the remaining affected certificates by 2024-05-01 after customer requests for more time. Mozilla asked NETLOCK to include analysis of what prevented timely revocation and remediation actions to prevent future delays, and later noted that the case would remain open until that was addressed. The thread also discussed NETLOCK’s certificate policy, CCADB data, and the relationship between its Hungarian regulatory obligations and WebPKI requirements. The bug was ultimately marked as a duplicate of bug 1947691.
- NETLOCK was notified that a TLS certificate issued under NETLOCK Trust EV CA 3 triggered a zlint error related to policy qualifiers.
- NETLOCK started revoking the affected certificates.
- NETLOCK revoked the misissued certificates that customers had not requested to keep valid longer.
- NETLOCK said all related certificates had been revoked.
- The bug was marked as a duplicate of bug 1947691.
- Netlock — NETLOCK opened the bug and attached an incident report saying some affected certificates were not revoked within the required number of days.
- Mozilla representative — Mozilla said delayed revocation cases require analysis of the factors that prevented timely revocation and remediation actions in the final incident report.
- Netlock — NETLOCK said it had corrected the profile and issued corrected certificates within the deadline, and that some customers needed more time because of internal procedures.
- Mozilla representative — Mozilla said the required remediation actions still had not been addressed and that the case would be closed around 2024-05-15 if progress continued.
- Netlock — NETLOCK said it was working with customers and that it would support automated solutions for partners.
- Netlock — NETLOCK said it would update the CCADB data and links as soon as possible.
- Netlock — NETLOCK said general CP/S changes must be notified 30 days in advance, but immediate modification is possible after prior consultation with authorities.
- Mozilla representative — Mozilla said the bug would remain open until at least 2025-02-01 while incident-reporting and compliance requirements were being worked on.
- Mozilla representative — Mozilla said a closure summary was needed and that NETLOCK needed to commit to timely revocation under BR 4.9.1.
- Netlock — NETLOCK said it had raised a new ticket, bug 1947691, and had answered the community questions in an appendix.
- Mozilla representative — Mozilla marked this bug as a duplicate of bug 1947691.